RE: Hacked NT/2K box
From: Chris Lynch, MCSE CCNAv2 (lynch00@msn.com)Date: 07/24/01
- Previous message: Gavin Millard: "Re: Worm ???"
- In reply to: H C: "RE: Hacked NT/2K box"
- Next in thread: Bronek Kozicki: "Re: Hacked NT/2K box"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Chris Lynch, MCSE CCNAv2" <lynch00@msn.com> To: "'H C'" <keydet89@yahoo.com> Subject: RE: Hacked NT/2K box Date: Mon, 23 Jul 2001 15:06:53 -0700 Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAAdIbHQDj1HEy4d8LgvrQfS8KAAAAQAAAAAptyL4wjpEGs1RrNcUFQ/QEAAAAA@msn.com>
I would have to dig it up somewhere. You can get the code from
http://neworder.box.sk. This is not by IIS, but rather to the security
risk via NetBIOS.
What I meant by "Windows NT has the capability for multiple shells/local
sessions" is that the NT Kernel can support it. The GUI just doesn't
have any way of switching between multiple sessions on a local NT
machine. The NT Kernel has always had this support, from version 4.
And, no. I haven't read anyone's article. I have just conversed with
other IT Professionals on the Net. They and I have concerns with the
home market. I have a concern with Microsoft's XP Personal firewall. I
know that IAS is a step above Proxy 2, but I haven't tested it out
myself.
When I find it, I'll forward it to you.
Chris Lynch
-----Original Message-----
From: H C [mailto:keydet89@yahoo.com]
Sent: Monday, July 23, 2001 1:36 PM
To: lynch00@msn.com; focus-ms@securityfocus.com
Subject: RE: Hacked NT/2K box
> Of course you can hack into an NT box like a
> Linux/UNIX box. I can
> generate code that will cause a buffer-overrun and
> will allow me Root
> like access (local/domain admin). I can then
> remotely install
> BackOrifice or some other trojan program.
Okay. Great. Can you show me? What code? Also, are
you refering to NT or IIS?
> Essentially, you are correct in saying that you
> cannot establish a
> remote console session. But you can with trojan
> programs. Well, NT
> has this capability built-in, but there isn't a way
> to exploit it
> unless you have Terminal Services installed and
> running.
NT doesn't come with Terminal Services by default.
You say that "NT has this capability built-in", and
then you say "there isn't a way to exploit it unless
you have Terminal Services installed and running." On
the face, that seems contradictory.
> Also, with XP being released, there would be no
> reason to say that a
> hacker wouldn't be able to use an XP box for DDoS
> attacks. Because
> XP will have RAW Sockets, instead of the
> conventional NT-based W32
> Sockets.
Ah, I see you've been reading Steve Gibson's page.
Win2K gives you access to raw sockets
programmatically, and it's already out.
__________________________________________________
Do You Yahoo!?
Make international calls for as low as $.04/minute with Yahoo! Messenger
http://phonecard.yahoo.com/
- Previous message: Gavin Millard: "Re: Worm ???"
- In reply to: H C: "RE: Hacked NT/2K box"
- Next in thread: Bronek Kozicki: "Re: Hacked NT/2K box"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|